Censorship-resistant communication systems that rely on popular Western tools often draw scrutiny in heavily censored regions, putting users at risk. We explore the alternative of using single-player games tolerated or developed within censored ecosystems to provide a covert communication medium. We introduce Trilobyte, a system that hides encrypted data in game state generated during regular gameplay, and uses shared cloud-synchronized gaming accounts to asynchronously communicate data. Trilobyte adopts a session-based model that allows users to remove or obfuscate traces between uses. We also introduce an optional server-based Trilobyte extension for asynchronous, monetized content delivery and analyze the additional attack surface it introduces. Under stated assumptions, Trilobyte supports plausibly deniable communications in our inspection-oriented adversary model, where adversaries may control gaming platforms and conduct repeated physical inspections of user devices. Our evaluation shows that Trilobyte can embed up to 5.3 MB of data in a one-hour session. We study the feasibility of shared-account covert communication over games accessible from both China and the U.S., and evaluate account acquisition through real-world purchases and rentals on Chinese gaming platforms. These results suggest that Trilobyte provides a practical, high-capacity approach to covert communication in inspection-oriented settings.
